(In reply to Bernhard Wiedemann from comment #24) > on 13.1 the workaround is > pam-config --add --unix-nullok This worked on a 13.1 and 13.2 host I just tried it on, including 'passwd -d' for the first times ever on any openSUSE installation. A question that does remain is is there readily discoverable and simple enough documentation such that a user new to openSUSE or dependent on its previous behavior won't be stymied to the extent I was. I create users via script before ever starting X or YaST. Before this bug report I had no idea anything about how the passwd command is allowed to work was configurable. The string pam is absent from release notes for 12.3, 13.1 and 13.2.